CVE Vulnerabilities

CVE-2008-5913

Published: Jan 20, 2009 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
3.6 LOW
AV:N/AC:H/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a temporary footprint and an in-session phishing attack.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 3.5 (including) 3.5 (including)
Firefox Mozilla 3.5.1 (including) 3.5.1 (including)
Firefox Mozilla 3.5.2 (including) 3.5.2 (including)
Firefox Mozilla 3.5.3 (including) 3.5.3 (including)
Firefox Mozilla 3.5.4 (including) 3.5.4 (including)
Firefox Mozilla 3.5.5 (including) 3.5.5 (including)
Firefox Mozilla 3.5.6 (including) 3.5.6 (including)
Firefox Mozilla 3.5.7 (including) 3.5.7 (including)
Firefox Mozilla 3.5.8 (including) 3.5.8 (including)
Firefox Mozilla 3.5.9 (including) 3.5.9 (including)
Red Hat Enterprise Linux 4 RedHat firefox-0:3.6.4-8.el4 *
Red Hat Enterprise Linux 5 RedHat devhelp-0:0.12-21.el5 *
Red Hat Enterprise Linux 5 RedHat esc-0:1.1.0-12.el5 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.6.4-8.el5 *
Red Hat Enterprise Linux 5 RedHat gnome-python2-extras-0:2.14.2-7.el5 *
Red Hat Enterprise Linux 5 RedHat totem-0:2.16.7-7.el5 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.2.4-10.el5 *
Red Hat Enterprise Linux 5 RedHat yelp-0:2.16.0-26.el5 *
Firefox Ubuntu dapper *
Firefox Ubuntu devel *
Firefox Ubuntu hardy *
Firefox Ubuntu lucid *
Firefox Ubuntu upstream *
Xulrunner-1.9 Ubuntu hardy *
Xulrunner-1.9 Ubuntu intrepid *
Xulrunner-1.9 Ubuntu jaunty *
Xulrunner-1.9 Ubuntu upstream *
Xulrunner-1.9.1 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu karmic *
Xulrunner-1.9.1 Ubuntu upstream *
Xulrunner-1.9.2 Ubuntu devel *
Xulrunner-1.9.2 Ubuntu hardy *
Xulrunner-1.9.2 Ubuntu jaunty *
Xulrunner-1.9.2 Ubuntu karmic *
Xulrunner-1.9.2 Ubuntu lucid *
Xulrunner-1.9.2 Ubuntu upstream *

References